LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 10-10-2010, 11:05 AM   #1
trist007
Senior Member
 
Registered: May 2008
Distribution: Slackware
Posts: 1,052

Rep: Reputation: 70
A question about kernel logs...


I have a question on the following kernel log entry. I'm taking a computer security class and I'm trying to buffer overflow a vulnerable version of the finger daemon. I'm running x86 32-bit. My question is in the log where it says "segfault at 90909090". Those 90s are NOPs, but is the logfile saying that there are NOPs at the EIP register or the return address. What does the log mean by segfault at xxxxxx? Is this what's in the EIP or the return address?

[code]
Oct 10 16:02:48 zeus xinetd[19165]: START: finger.stack pid=20764 from=127.0.0.1
Oct 10 16:02:48 zeus xinetd[19165]: EXIT: finger.stack signal=11 pid=20764 duration=0(sec)
Oct 10 16:02:48 zeus kernel: [1042664.345881] in.fingerd.stac[20764]: segfault at 90909090 ip 0000000045faacc3 sp 00000000ffffd284 error 6 in libc-2.5.so[45f3b000+152000]
[\code]
 
Old 10-10-2010, 12:42 PM   #2
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
Same as anywhere else; that piece of code tried to a) access RAM
that didn't belong to it, or b) you might have a faulty stick of
memory in your machine.


Cheers,
Tink
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about the logs viewer application (/var/logs) balteo Linux - General 1 11-20-2009 11:13 PM
[SOLVED] question about RH security logs unix1adm Linux - Security 32 11-19-2009 02:37 AM
Question about logs alpha_lt Linux - Newbie 6 10-27-2009 11:45 AM
tcpdump logs question tgo Linux - Security 5 07-23-2006 05:07 AM
question about QMAIL logs zurron Linux - Software 15 09-06-2004 03:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 08:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration